Natalya Tlyapova (@sc4rlet9) 's Twitter Profile
Natalya Tlyapova

@sc4rlet9

ID: 3400950465

calendar_today03-08-2015 07:00:58

17 Tweet

197 Followers

29 Following

Maxim Goryachy (@h0t_max) 's Twitter Profile Photo

Today we're[+Mark Ermolov and Dmitry Sklyarov]disclosing the technique allowing to modify #Intel #Microcode on the fly! For the first time you have the ability to intercept control flow at such a low level. We've developed the microcode patch that changes the processor model string as PoC

OffSec (@offsectraining) 's Twitter Profile Photo

📢 ICYMI, we launched a new course: EXP-301! In Windows User Mode Exploit Development, you’ll learn how to create custom exploits, bypass security mitigations, and reverse-engineer bugs. Get your questions answered in our FAQs: offs.ec/3tbz1EC

📢  ICYMI, we launched a new course: EXP-301! In Windows User Mode Exploit Development, you’ll learn how to create custom exploits, bypass security mitigations, and reverse-engineer bugs. 

Get your questions answered in our FAQs: offs.ec/3tbz1EC
Cyber Advising (@cyber_advising) 's Twitter Profile Photo

WINDOWS KERNEL ZERO-DAY EXPLOIT (CVE-2021-1732) IS USED BY BITTER APT IN TARGETED ATTACK ti.dbappsecurity.com.cn/blog/index.php…

WINDOWS KERNEL ZERO-DAY EXPLOIT (CVE-2021-1732) IS USED BY BITTER APT IN TARGETED ATTACK
ti.dbappsecurity.com.cn/blog/index.php…
PT SWARM (@ptswarm) 's Twitter Profile Photo

🔥New article: "Swarm of Palo Alto PAN-OS vulnerabilities". Two RCEs and other bugs found by our researchers Mikhail Klyuchnikov & Nikita Abramov. swarm.ptsecurity.com/swarm-of-palo-… Full analysis 👆

🔥New article: "Swarm of Palo Alto PAN-OS vulnerabilities".

Two RCEs and other bugs found by our researchers Mikhail Klyuchnikov & Nikita Abramov.

swarm.ptsecurity.com/swarm-of-palo-…

Full analysis 👆
Binni Shah (@binitamshah) 's Twitter Profile Photo

Imhex : A Hex Editor for Reverse Engineers, Programmers and people that value their eye sight when working at 3 AM : github.com/WerWolv/ImHex credits WerWolv

Imhex : A Hex Editor for Reverse Engineers, Programmers and people that value their eye sight when working at 3 AM : github.com/WerWolv/ImHex credits <a href="/WerWolv/">WerWolv</a>
Volexity (@volexity) 's Twitter Profile Photo

Volexity has identified multiple 0-day exploits in Microsoft Exchange resulting in authentication bypass and RCE. Actively exploited in the wild since at least January 2021. More here: volexity.com/blog/2021/03/0… #threatintel #dfir #infosec

Volexity has identified multiple 0-day exploits in Microsoft Exchange resulting in authentication bypass and RCE. Actively exploited in the wild since at least January 2021. More here: volexity.com/blog/2021/03/0…
 #threatintel #dfir #infosec
PT SWARM (@ptswarm) 's Twitter Profile Photo

VMware fixed an Unauth RCE in View Planner (CVE-2021-21978) found by our researcher Mikhail Klyuchnikov. Advisory: vmware.com/security/advis…

VMware fixed an Unauth RCE in View Planner (CVE-2021-21978) found by our researcher Mikhail Klyuchnikov.

Advisory: vmware.com/security/advis…
PT SWARM (@ptswarm) 's Twitter Profile Photo

🚀Join our new telegram channel! It's where we share lots of articles, vulnerabilities, and scripts, not necessarily authored by us, that we find interesting. More stuff coming soon! 👉 t.me/ptswarm

PT SWARM (@ptswarm) 's Twitter Profile Photo

New article "How we bypassed bytenode and decompiled Node.js (V8) bytecode in Ghidra" by our researcher Sergey Fedonin. swarm.ptsecurity.com/how-we-bypasse…

New article "How we bypassed bytenode and decompiled Node.js (V8) bytecode in Ghidra" by our researcher Sergey Fedonin.

swarm.ptsecurity.com/how-we-bypasse…
Slava Moskvin | Path Cybersec (@slava_moskvin_) 's Twitter Profile Photo

If you are interested in Ghidra plugins, this is how you can significantly improve decompiler output by dynamically injecting P-Code. This is what I used in our Ghidra Node.JS plugin github.com/PositiveTechno…. At the time of writing this mechanism was poorly documented. #Ghidra

PT SWARM (@ptswarm) 's Twitter Profile Photo

SonicWall fixed a Post-Auth RCE (CVE-2021-20026) in Network Security Manager and an Unauth Buffer Overflow (CVE-2021-20027) in SonicOS found by our researcher Nikita Abramov. Advisory: psirt.global.sonicwall.com/vuln-detail/SN…

SonicWall fixed a Post-Auth RCE (CVE-2021-20026) in Network Security Manager and an Unauth Buffer Overflow (CVE-2021-20027) in SonicOS found by our researcher Nikita Abramov.

Advisory: psirt.global.sonicwall.com/vuln-detail/SN…
Alexander Popov (@a13xp0p0v) 's Twitter Profile Photo

I've published the article covering my talk at ZeroNights! Improving the exploit for CVE-2021-26708 in the Linux kernel to bypass LKRG a13xp0p0v.github.io/2021/08/25/lkr… Slides: a13xp0p0v.github.io/img/CVE-2021-2… PoC exploit demo video: youtube.com/watch?v=O6rsuG… Enjoy!

I've published the article covering my talk at <a href="/ZeroNights/">ZeroNights</a>!

Improving the exploit for CVE-2021-26708 in the Linux kernel to bypass LKRG
a13xp0p0v.github.io/2021/08/25/lkr…

Slides: 
a13xp0p0v.github.io/img/CVE-2021-2…

PoC exploit demo video: youtube.com/watch?v=O6rsuG…

Enjoy!
PT SWARM (@ptswarm) 's Twitter Profile Photo

💳PAX Technology fixed three vulnerabilities discovered by our researcher Artem Ivachev. 💰When chained together these vulnerabilities allow the interception of user card data and the sending of arbitrary data to the processing of the acquiring bank.

💳PAX Technology fixed three vulnerabilities discovered by our researcher Artem Ivachev. 

💰When chained together these vulnerabilities allow the interception of user card data and the sending of arbitrary data to the processing of the acquiring bank.